Create or retry Checkout with a trusted publication decision
Requires the customer credential’s authenticated actor, billing:write, live billing, and a server-signed publication assertion. The assertion must use EdDSA, issuer promotion-auth-adapter, audience promotion-account, operation checkout, and a positive lifetime of at most five minutes. Its sub and team_id must match the customer credential, and its operation_id, home_region, decision, success_url and cancel_url must exactly match the body. The region must match the receiving cell.
The decision is committed with the fresh generation before Stripe session creation. publication_failed preserves paid access without new automatic promotion credit; standard uses existing eligibility checks. Retry the same operation and body with a renewed assertion after a lost response. Existing generations retain their original payer and decision. A changed or retired operation conflicts; do not fall back to the legacy creation route on an error or an older server’s missing route.
Bodies over 4096 bytes and unknown fields are rejected. Redirects must match the regional API’s allowed billing redirect configuration.
Authorizations
Server-only Ed25519 JWT binding the authenticated actor and team to the exact Checkout intent.